RFC 2617: HTTP Authentication: Basic and Digest Access Authentication
This RFC has been replaced. Do not implement against it for new work — it was formally obsoleted by RFC 7235, RFC 7615, RFC 7616, RFC 7617.
Current document in this lineage: RFC 7616 — HTTP Digest Access Authentication; RFC 7617 — The 'Basic' HTTP Authentication Scheme; RFC 9110 — HTTP Semantics; RFC 9111 — HTTP Caching; RFC 9112 — HTTP/1.1
In plain English — editorial summary, not part of the RFC
This document provides the specification for HTTP's authentication framework, the original Basic authentication scheme and a scheme based on cryptographic hashes, referred to as "Digest Access Authentication". [STANDARDS-TRACK]
Document record
- Document ID
- RFC2617
- Published
- June 1999
- Authors
- J. Franks; P. Hallam-Baker; J. Hostetler; S. Lawrence; P. Leach; A. Luotonen; L. Stewart
- Status
- DRAFT STANDARD
- Stream
- IETF
- Area
- app
- Pages
- 34
- Also known as
- —
- Obsoletes:
- RFC 2069
Topics
Standards lineage
This document is one revision in a chain of 21 RFCs, each formally replacing the one before it.
- RFC 2068 (1997)
- RFC 2069 (1997)
- RFC 2145 (1997)
- RFC 2616 (1999)
- RFC 2617 (1999)
- RFC 2818 (2000)
- RFC 7230 (2014)
- RFC 7231 (2014)
- RFC 7232 (2014)
- RFC 7233 (2014)
- RFC 7234 (2014)
- RFC 7235 (2014)
- RFC 7238 (2014)
- RFC 7538 (2015)
- RFC 7615 (2015)
- RFC 7616 (2015)
- RFC 7617 (2015)
- RFC 7694 (2015)
- RFC 9110 (2022)
- RFC 9111 (2022)
- RFC 9112 (2022) ✓
Referenced by
4 later RFCs formally update or obsolete part of this document.
- RFC 7235Hypertext Transfer Protocol (HTTP/1.1): AuthenticationObsoleted
June 2014
- RFC 7615HTTP Authentication-Info and Proxy-Authentication-Info Response Header FieldsObsoleted
September 2015
- RFC 7616HTTP Digest Access AuthenticationCurrent
September 2015
- RFC 7617The 'Basic' HTTP Authentication SchemeCurrent
September 2015
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 6331Moving DIGEST-MD5 to HistoricCurrent
July 2011
- RFC 2616Hypertext Transfer Protocol -- HTTP/1.1Obsoleted
June 1999
- RFC 2965HTTP State Management MechanismObsoleted
October 2000
- RFC 2227Simple Hit-Metering and Usage-Limiting for HTTPCurrent
October 1997
- RFC 3253Versioning Extensions to WebDAV (Web Distributed Authoring and Versioning)Current
March 2002
- RFC 2585Internet X.509 Public Key Infrastructure Operational Protocols: FTP and HTTPCurrent
May 1999
- RFC 2527Internet X.509 Public Key Infrastructure Certificate Policy and Certification Practices FrameworkObsoleted
March 1999
- RFC 2511Internet X.509 Certificate Request Message FormatObsoleted
March 1999
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?